Metrics
Affected Vendors & Products
No advisories yet.
Solution
This issue was fixed in versionĀ 4.0.260123.1 of the runZero Platform
Workaround
No workaround given by the vendor.
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H (6.4 Medium). This issue was fixed in version 4.0.260123.1 of the runZero Platform. | |
| Title | runZero Platform SQL injection in saved queries | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-04-07T14:50:25.766Z
Reserved: 2026-04-01T19:51:10.741Z
Link: CVE-2026-5372
Updated: 2026-04-07T14:44:19.479Z
Status : Received
Published: 2026-04-07T15:17:46.973
Modified: 2026-04-07T15:17:46.973
Link: CVE-2026-5372
No data.
OpenCVE Enrichment
No data.